Re: Help: Tracking Down Errant SMTP Server.

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hello's I'm living in spam Nightmare and need some help tracking
down an errant SMTP engine that is wreaking havoc on users email
accounts.

Arrant, too, I'd say. :)

From the looks of things a users email address is being used by an
errant smtp engine out there.

It'd be wishful thinking to assume it's just one "engine" -- likely a
load of zombies.

The SMTP engine is sending out massive amounts of emails and
specifying this users account as the "Return To Address".

Classic 'Joe Job'. There is nothing inherent in the SMTP protocol that
prohibits what we perceive as "impersonation" of an envelope sender.

Originally, JJs were largely malicious, deliberate DoS attacks against
specific senders. Later, spammers started using large ranges of sender
addresses to ensure they'd have a legit return address and thus pass
sender address verification (SAV) checks. Typically, JJs of the spam
type calm down after several days, as each address falls out of
rotation. However, JJs *designed* for spam can malfunction -- it is
both amusing and horrifying when the botnets malfunction, spewing
e-mail without variable substitution and such -- in which case they
would be as overwhelming as a deliberate attack. It would be hard to
tell one from the other unless the victim had very recently made some
enemies, such as by starting up an anti-spam business, or really any
kind of extreme personal or corporate antagonism where the other side
is tech-savvy.

The only way to attempt to proactively prevent JJs is to publish an
SPF policy for your domain. However, SPF failures are enforced by a
small enough fraction of remote servers that this will have little
practical effect. Still, publishing SPF may have an ethical (and
perhaps legal?) benefit in that it shows that you have made a
good-faith effort to highlight impersonation by listing the servers
you authorize to send mail from your domain... thus, all others are
contravening your published policy and you can't be as responsible for
them as you would be without the public record.

This is some form of DNS as the user's email account is now
un-usable.

DoS. :)

What is the best way to track down the sender (s) of these email
messages, and has anyone else experienced this problem?

Many millions have experienced this problem. As I said, it should
abate if it is not a deliberate targeting of this account. You can
inspect the headers of the NDRs to get an idea of how many different
IPs generated the original messages. If by some chance it is a very
small set of IPs, you can pursue it with the ISP and also with (I
understand) law enforcement, as there is case law establishing that a
crime has been committed. But chances are, you'll see a huge range of
spam zombie IPs with no responsible party.

--Sandy
.



Relevant Pages

  • Re: Multiple copies of E-Mail messages in OE6
    ... The problem is with the sender or their email provider if it's only one ... >>> During the past 3 days I have been receiving multiple copies of an ... >>> E-Mail program OE6 ... >> POP3 account? ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: retrieve the sender address using Extended MAPI (C++)
    ... It will contains the account id, which you will then need to use with the ... IMAPISession::QueryIdentity to retrieve the current user details. ... the sender address before the message is send out. ... LPSPropTagArray lpNamedPropTags = NULL; ...
    (microsoft.public.win32.programmer.messaging)
  • Re: Standard sender with machine account and/or user account
    ... why not use an account ... based sender with appropriate rights on both servers? ... > site server. ... > Primary site and in the secondary site server. ...
    (microsoft.public.sms.setup)
  • Re: Standard sender with machine account and/or user account
    ... do is push advanced client to the secondary site, ... To do that i need to configure a user account for the sender. ... >> Because of this i can not install advanced agent in the secondary site, ...
    (microsoft.public.sms.setup)
  • Defaulting to another users inbox
    ... We are running 2K with exchange server 2000 with 200 users accessing ... We have one user who will sometimes receive another users email ... loggon and then start up Exchange and will have the other account. ... running mandatory profiles. ...
    (microsoft.public.exchange.admin)